A customer requests that a known spyware threat signature be triggered based on a rate of occurrence, for example, 10 hits in 5 seconds. How is this goal accomplished?
A.
Create a custom spyware signature matching the known signature with the time attribute
B.
Add a correlation object that tracks the occurrences and triggers above the desired threshold
C.
Submit a request to Palo Alto Networks to change the behavior at the next update
D.
Configure the Anti-Spyware profile with the number of rule counts to match the occurrence frequency
The answer is A
This is exactly how brute force threat ID is triggered. It watches a separate threat ID (failed auth attempt, which is an alert by default), and has a time event that if that monitored threat ID is triggered x times in y seconds by the same source IP, then the brute force threat is triggered, and can then take a different action such as block IP.
You would create a custom spyware profile to do the same; trigger when x has occurred y times in z seconds.
A correlation object does not trigger anything. It pulls data from multiple sources and can create a log entry when it's defined conditions are met.
To trigger a known spyware threat signature based on a rate of occurrence (e.g., 10 hits in 5 seconds), you need to add a correlation object that tracks the occurrences and triggers an alert or action when the specified threshold is met. This correlation object monitors the frequency of the spyware signatures and ensures that action is taken only when the threshold is exceeded, providing more granular control over threat detection and response.
References: Palo Alto Networks Threat Prevention and Correlation Objects documentation.
Correct answer it´s b B. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-the-automated-correlation-engine/automated-correlation-engine-concepts/correlation-object
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
milkyway2000
9 months, 2 weeks agoVenomX51
9 months, 3 weeks agoMaxG
10 months agoJerar
10 months, 4 weeks agoJerar
11 months, 1 week agodavidpm
11 months, 2 weeks agonobody165456131354
1 year, 6 months agofreepotatoes
2 years, 1 month ago